SITCON 學生計算機年會 tickets ticket analytics route lacks event-scoped access check - HITCON ZeroDay

Vulnerability Detail Report

Vulnerability Overview

  • ZDID: ZD-2026-00807
  •  發信 Vendor: SITCON 學生計算機年會
  • Title: SITCON 學生計算機年會 tickets ticket analytics route lacks event-scoped access check
  • Introduction: The public SITCON tickets backend exposes a ticket analytics admin route under eventAdmin admission but without the event-scoped ticket access preHandler used by neighboring ticket routes.

處理狀態

目前狀態

公開
Last Update : 2026/09/19
  • 新提交
  • 已審核
  • 已通報
  • 已修補
  • 未複測
  • 公開

處理歷程

  • 2026/06/03 19:46:14 : 新提交 (由 老狼 更新此狀態)
  • 2026/06/10 12:48:26 : 審核中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/09/18 15:32:31 : 已修補 (由 組織帳號 更新此狀態)
  • 2026/09/19 03:00:09 : 公開 (由 HITCON ZeroDay 平台自動更新)

詳細資料

  • ZDID:ZD-2026-00807
  • 通報者:skyknow (老狼)
  • 風險:中
  • 類型:存取控制缺陷 (Broken Access Control)

參考資料

攻擊者可經由該漏洞取得、修改、刪除系統中的其他使用者的資料,或連線至高權限使用者的頁面。

OWASP Top 10 - 2017 A5 - Broken Access Control
https://www.owasp.org/index.php/Top_10-2017_A5-Broken_Access_Control

CWE-284: Improper Access Control
https://cwe.mitre.org/data/definitions/284.html
(本欄位資訊由系統根據漏洞類別自動產生,做為漏洞參考資料。)

相關網址

https://zeroday.hitcon.org/bug-bounty/list
https://github.com/sitcon-tw/tickets
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/routes/admin/tickets.ts#L515-L576
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/routes/admin/tickets.ts#L137-L139
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/middleware/auth.ts#L151-L341

敘述

Summary

圖片

The public sitcon-tw/tickets backend mounts admin routes under /api/admin and protects the router with requireAdminOrEventAdmin. That guard allows both admin and eventAdmin roles.

Neighboring ticket routes apply requireEventAccessViaTicketId so an eventAdmin can only access tickets for assigned events. However, GET /api/admin/tickets/:id/analytics defines only a schema and no route-level preHandler.

If the deployed system follows this source, an event-scoped organizer may be able to retrieve analytics for another event's ticket by supplying that ticket id.

Source evidence

  • backend/routes/admin.ts:17 installs the top-level admin router guard.
  • backend/middleware/auth.ts:151 allows eventAdmin into that router.
  • backend/middleware/auth.ts:341 defines requireEventAccessViaTicketId.
  • backend/routes/admin/tickets.ts:137 shows the neighboring ticket detail route.
  • backend/routes/admin/tickets.ts:139 applies requireEventAccessViaTicketId to that neighboring detail route.
  • backend/routes/admin/tickets.ts:515 defines GET /tickets/:id/analytics.
  • backend/routes/admin/tickets.ts:516-518 defines only the schema for the analytics route and no preHandler.
  • backend/routes/admin/tickets.ts:531 fetches the ticket by supplied id.
  • backend/routes/admin/tickets.ts:549 groups registrations by status.
  • backend/routes/admin/tickets.ts:560 computes daily sales by ticketId.
  • backend/routes/admin/tickets.ts:576 returns the analytics object.

Local-only reproduction

圖片

I validated the source path using a local static model only:

python3 findings/20260603-1211-hitcon-sitcon-ticket-analytics-no-event-access/local-repro.py

The script checks admin router role admission, neighboring ticket route guard pattern, missing analytics route preHandler, and analytics data returned from the route. It reports:

{
  "observed_candidate_behavior": true,
  "network_requests": 0,
  "validation_mode": "LOCAL_SOURCE_STATIC_MODEL"
}

Impact

Ticket analytics can reveal operational and business-sensitive event metrics, including sales count, revenue, available quantity, status distribution, and date-level sales trends. Cross-event access would let an event-scoped organizer view analytics for events outside their permission set.

This report is intentionally conservative: I validated public source and local control flow only. I did not prove live production exploitability.

Safety boundary

圖片

This report is based on public source and local static validation. I did not log in to SITCON, request SITCON production/private endpoints, query any real ticket analytics endpoint, access real ticket/registration/sales data, use scanners/fuzzing/DoS, contact SITCON, publish an issue, or open a PR.

修補建議

Add preHandler: requireEventAccessViaTicketId to GET /tickets/:id/analytics, matching the neighboring ticket detail, update, and delete routes.

擷圖

留言討論

聯絡組織

 發送私人訊息
您也可以透過私人訊息的方式與組織聯繫,討論有關於這個漏洞的相關資訊。
;